Parte de viajeros. RD 933/2021. SES.HOSPEDAJES. Three names used in Spain as though they were synonyms, for three different things: the submission itself, the rule that demands it, and the Ministry portal it travels through.
That tangle of labels survived the successive moratoriums that held the register back, and it still feeds two expensive mistakes: assuming the clock only starts at check-in, and assuming the old paper report still counts for something.
Royal Decree 933/20211 is the rule that settles all of it for anyone carrying out lodging activities in Spain. It sets who must comply, what data to collect, the deadline for sending it, how long to keep it, and what happens if you don’t. If you run a hotel, an apartment, a rural house or any regulated lodging, it applies to you directly.
Royal Decree 933/2021: start date and who has to comply
The decree was published in the BOE on 27 October 2021 and came into force six months later. Its third final provision set 2 January 2023 for the communication obligations, and the consolidated text still says exactly that today, with no later amendments2.
The date was never moved by amending the rule. It was moved by the Ministry of the Interior, which applied successive moratoriums while it built the platform and switched the register on for real on 2 December 2024. From that day, hotels, apartments, booking platforms, travel agencies and vehicle rental firms report their customers’ data3.
Many lodgings had spent years filing the report through Hospederías, the Guardia Civil platform that SES.HOSPEDAJES replaced and that no longer accepts reports.
The scope leaves no room for size or legal form:
“The provisions of this royal decree shall apply throughout the national territory to lodging activities and to the rental of motor vehicles without a driver, whatever the arrangement, the legal personality of the holder or the model of organisation.”
It makes no difference whether you rent out one flat in your own name or run forty through a company: the obligation is the same. The practical list of who is inside:
- Hotels, hostels, guesthouses.
- Tourist apartments and tourist-use dwellings (VUT).
- Rural houses, youth hostels, mountain refuges, campgrounds.
- Private vacation rentals on platforms (Airbnb, Booking, VRBO, etc.) when offered as tourist lodging.
- Seasonal rentals with lodging services.
What about pure seasonal rental, with no lodging services? The criterion the Ministry applies is purpose, not duration: the decree applies whatever the arrangement and whatever the length of the contract, provided the purpose is something other than housing4. A seasonal let to a student as their home falls outside; the same flat rented by the week to tourists falls inside. If your case sits on the line, check with your advisor.
And the guest report stands in for nothing. The tourist licence is granted by your autonomous community and runs on its own track (what each one asks for). The single rental registry, the NRUA, was a third and separate obligation, and Spain’s Supreme Court annulled it in 2026 (what survives).
The four RD 933/2021 obligations
Since 2 December 2024, every accommodation has to:
- Register the activity before starting it: the lessor company’s and the establishment’s details if the lodging is professional, or the owner’s and the property’s if it is not (Article 6.1)5.
- Collect the data of every traveller staying at the property.
- Submit the guest report to the Spanish Ministry of the Interior through SES.HOSPEDAJES.
- Report the lodging reservation with the details of the stay (dates, number of guests, type of accommodation) when the booking arrives directly.
The first one is the filing almost nobody knows exists. Registering on SES.HOSPEDAJES is not a commercial formality you get around to before your first guest report: it is the Article 6.1 obligation. And it has a deadline of its own, ten days from the completion of the administrative formalities and in any case before you actually start trading (Article 6.2)5.
Nor is it done once and forgotten. Article 6.1 closes with a sentence worth reading slowly: “Any change to the data indicated shall give rise to the obligation of a fresh communication.” A new phone number, a new email address or a change of holder all have to be filed again.
When the booking arrives through a platform such as Booking or Airbnb, the reservation report falls to the platform, which is an obliged subject in its own right. The Ministry’s criterion for splitting it is position in the chain: where several intermediaries take part in the commercial relationship, the data is reported by the one holding a direct and final contractual relationship with the customer4. The guest report is never split: that one is always yours.
The decree also separates two regimes, depending on whether the lodging is carried out professionally, and the border is the tax register. You act professionally if you are entered in the Censo de Empresarios, Profesionales y Retenedores, the Spanish register of businesses and professionals4, which is where practically every tourist accommodation manager sits. What changes between the two regimes is the record-keeping and retention (Article 5)6, not the reporting (Article 6)5:
| Obligation | Professional lodging | Non-professional lodging |
|---|---|---|
| Prior registration of the activity (art. 6.1) | Yes | Yes |
| Computerised register with the Annex I data (art. 5.1) | Yes | Exempt (art. 5.4) |
| Retention for three years (art. 5.3) | Yes | Exempt (art. 5.4) |
| Reporting of guest reports and reservations (art. 6.3) | Yes | Yes |
| Submission by electronic procedures (art. 6.4) | Mandatory | Exempt |
That last exemption is theoretical. Article 6.4 lets non-professional lodging report by non-electronic means “by the procedure to be determined”, and that procedure has never been published5. In practice SES.HOSPEDAJES is the only channel and the old paper reports are no longer accepted.
Royal Decree 933/2021: what guest data must be collected
The rule requires, as a minimum:
- Full name (first name, first surname, and second surname for Spanish documents).
- Sex and date of birth.
- Nationality.
- Type and number of ID document. Annex I names three types: DNI, passport and TIE7.
- Support number (required for the Spanish DNI).
- Usual residential address.
- Contact phone and/or email.
- Relationship (parentesco) to an accompanying adult, required while the traveller is a minor in law, so up to 18.
The NIE is not on that list, and that is not an oversight: the NIE is a number, not a document. A guest handing you a TIE is giving you their NIE printed on it, and a guest handing you the green EU registration certificate is not giving you an identity document at all. The differences, document by document, are in NIE, TIE, NIF and DNI.
The signature has a threshold of its own, and it is fourteen years, not eighteen:
“The entry reports for the use of lodging services must be signed by every person over fourteen years of age who uses them, in accordance with the system and model established. In the case of persons under fourteen years of age, their data shall be provided by the adult they are accompanied by.”
So a fifteen-year-old guest signs their own report, and a ten-year-old does not sign but is recorded anyway. Article 5.1 requires the computerised register to hold the Annex data “including, where applicable, the data of persons under fourteen years of age”6. How the rule applies to children and teenagers is in Minors in guest registration.
Accuracy is the establishment’s responsibility, not the guest’s. Article 4.3 makes the lodging answerable for the report’s data matching the documents that prove identity, documents that “shall be exhibited or provided by the users of these services”1. The practical consequence is uncomfortable: if a guest resists giving the support number of their DNI, the report goes out incomplete, and irregularities in completing it are the minor infraction of Article 8.3.a).
On top of the traveller’s data, the lodging reservation adds the contract, its performance, the property and the payment, field by field.
Unattended check-in: what RD 933/2021 allows
Most tourist apartments have no front desk. The guest turns up at two in the morning, opens a key box or taps a code into the lock and goes up alone, and sometimes nobody from the property sees them at all during the stay. The question that follows is whether a guest report collected that way holds up.
It holds up, and Article 4.3 anticipated it. Two pairs of words are worth reading slowly: the establishment answers for the data matching the documents or systems that prove identity, and those are to be exhibited or provided by the users1. Exhibiting is holding the card up across a counter; providing is supplying it by another route. The 2021 rule was not written only for a reception desk with somebody behind it.
Spain’s Ministry of the Interior says so plainly when answering how the data should be collected:
“Establishments may collect the information by any system that allows the accuracy of the data to be verified, even without their physical presence being necessary, and provided the system is compatible with compliance with the rules in force, especially on data protection.”
The next question closes the other half: electronic devices that let the obliged subject verify the accuracy of the data remotely are valid, carrying the same duties of fairness, transparency and information to the guest as any other processing4.
What stops being a requirement is physical presence. What remains one is the system that allows the accuracy to be verified: collecting the data remotely does not move the Article 4.3 responsibility, and a form the guest fills in with nothing behind it verifies nothing.
What counts as verification when the guest is not in front of you
The AEPD, Spain’s data protection agency, set out the mechanisms in its note of 17 June 2025, and there are three8:
- a digital certificate belonging to the traveller;
- a check against the payment method details, which have to match what was declared;
- a security code sent to the guest’s phone or email, two fields Annex I already obliges you to collect.
The agency does not close the list, but it leaves the burden where it was: the one who has to assess whether a mechanism is compatible with GDPR is the controller, meaning you. What appears in no version of that list is asking for a photo of the document over WhatsApp, and that route already has AEPD fines behind it.
What the manager does when arrival is by key box
With self-entry, check-in moves ahead of the arrival instead of happening at it:
- Send the check-in link when you confirm the booking, not on the day of arrival. If a field is missing you chase it in writing and with room to spare, not at two in the morning.
- Ask for the full set of Annex I fields, support number included, and the signature of every traveller over fourteen.
- Verify with one of the three mechanisms and record which one you used for each stay.
- File the guest report at the start of the stay, not when the form comes back.
The fourth point is the one most often confused. Collecting early is a convenience for you: the Article 6.3 clock stays tied to the start of the contracted services, so a check-in completed three days ahead neither brings the filing forward nor delays it. What it does buy you is room to fix a field before the deadline starts running.
One limit does not come from RD 933/2021. Collecting the data remotely is one thing and handing over keys with nobody there is another, and the second belongs to each autonomous community. Asturias, since February 2026, requires a reception service to be provided in person or remotely within 24 hours of arrival, and bans handing over keys through key boxes placed on the public highway or overhanging it9. The state decree lets you collect the data without seeing the guest; your regional tourism rules may still tell you how they come through the door, and what each one asks for is in tourist licence by region.
Spain guest data law 933/2021: deadline for submission
This is the question that comes up most, and Article 6.3 settles it in a single sentence holding two clocks:
“This communication shall be made immediately, and in any event within no more than 24 hours, respectively, from the following moments: a) On making the reservation or formalising the contract or, where applicable, its cancellation. b) At the start of the contracted services.”
The word almost nobody reads is “respectively”: each of those two moments opens its own 24-hour deadline. The clock does not start only at check-in, and a cancellation starts it too.
In practice:
- The guest report is sent to the Ministry within the first hours of the stay.
- The lodging reservation, when it is yours to file, can be sent earlier (when the booking is confirmed) or together with the guest report.
- A cancellation is reported if the reservation had already been submitted and the guest doesn’t arrive.
Sending a report a week later is an untimely communication. Sanctionable.
How long must guest data be kept?
“The data in the computerised register must be kept for a period of three years counted from the end of the service or contracted provision.”
Three years, and the clock starts when the stay ends, not at check-in and not on the day you filed the report. After that period the data must be deleted or anonymised: the retention is fixed by the rule, not discretionary, and keeping it longer without an additional legal basis would breach GDPR.
Your software should purge automatically. If you plan to do it by hand, you won’t.
The data you send does not stay in the portal either. Article 7.1 keeps it in two files held by the Secretary of State for Security. Its processing is reserved to the State security forces “in the field of crime prevention, detection and investigation”, with access also for the courts and the public prosecutor1. It is not a commercial or tourism database, and that is the short answer when a guest asks what their data is used for.
SES.HOSPEDAJES: what it is and how to get access
SES.HOSPEDAJES is the Spanish Ministry of the Interior’s platform, run by the Secretary of State for Security, and it is where you submit guest reports and lodging reservations. The SES.HOSPEDAJES guide walks the platform screen by screen.
To access SES.HOSPEDAJES you need:
- A lessor code assigned by the system at registration.
- An establishment code for each property.
- Access credentials (SOAP username and password) for automatic submission.
The holder does not have to file in person: the communication may be made through a third party as long as that party is authorised by the obliged subject in one of the forms admitted in law4. That is what lets you delegate it to an accountant or to software. And past a handful of properties you need to, because every stay is two communications and each one carries its own 24-hour clock.
How to request each credential, step by step, is in How to obtain SES.HOSPEDAJES credentials. When a submission is rejected, the portal answers with a numeric code, and the most frequent ones are in SES.HOSPEDAJES error codes. And when the portal itself is what has failed, rather than your submission, the symptoms are in SES.HOSPEDAJES not working.
What is sent to SES.HOSPEDAJES: guest report and reservation
A normal stay generates two separate communications:
- Guest report: the personal data of each registered guest.
- Lodging reservation: the contract details and the details of the stay.
Point 4 of section A) of Annex I spells out what the reservation carries, and it is more than most people expect7:
- Contract details: reference number, date and signatures.
- Performance of the contract: date and time of entry, date and time of exit.
- Property details: full address, number of rooms and whether it has an Internet connection.
- Payment details: type, identification of the means, holder, card expiry date and date of payment.
Section B), the non-professional regime, asks for the same, with the property details gathered under a point of their own. The Annex makes none of those blocks conditional on the type of accommodation or on the length of the stay.
They do not travel together. On the portal you pick one communication type or the other, and each carries its own trigger and its own 24-hour deadline: the booking goes out when the reservation is made, the guest report when the stay begins.
Nor does the same party always file them. The guest report is always the lodging’s; the booking falls to whoever took the reservation, which on a platform sale is the platform. The full split, mixed cases included, is in reserva de hospedaje or parte de viajeros. Once processed, each communication gets its own acceptance confirmation, or the detail of the errors to fix.
RD 933/2021 and payment card data: is it mandatory?
A question that comes up in every conversation with owners. Yes, it is mandatory: Annex I includes the payment block among the transaction data that travels with the lodging reservation. What you have to collect:
- Type of payment method (cash, credit card, payment platform, bank transfer).
- Holder of the payment method.
- Identification of the means: for a card, the type and the number; for a transfer, the account IBAN.
- Expiry date of the card.
- Date of payment.
That list is worth reading twice, because Annex I asks for the card number and its expiry date, not just the last four digits7. The one thing that appears nowhere in the Annex is the CVV, which is never reported.
And there is no small print softening it. The Annex asks for the payment block under both regimes it distinguishes, professional and non-professional, without conditioning it on the type of accommodation or the length of the stay. The note with which the Ministry switched the register on puts it the same way: on the commercial side you must specify the means of payment and identify the transaction whenever it is settled by credit card, bank transfer or digital payment platform3.
This is payment data travelling inside an administrative filing, so it deserves handling to match. Collecting it in a spreadsheet or over email is precisely what not to do.
Penalties for not filing the parte de viajeros
Article 8 of RD 933/2021 sets no amount at all: it refers to Chapter V of Organic Law 4/2015 on public safety and confines itself to classifying four kinds of conduct10. The figures come from Article 39.1 of that law11:
| Conduct | Classification | Fine |
|---|---|---|
| Absence of the documentary registers | Serious | €601 to €30,000 |
| Omission of the mandatory communications | Serious | €601 to €30,000 |
| Irregularities or deficiencies in completing the registers | Minor | €100 to €600 |
| Mandatory communications filed outside the deadline | Minor | €100 to €600 |
There is no very serious infraction through this route. And €30,000 is the ceiling of the bracket, not the fine for an ordinary breach: for serious infractions, committing one sets the fine at the minimum degree, €601 to €10,400, and moving up a degree requires proving closed circumstances.
The fine may not come alone. Article 39.2.d) allows the establishment to be closed for up to six months for serious infractions in the field of the matters regulated in Chapter IV of that same law. And Chapter IV is where Article 25 sits, subjecting activities relevant to public safety to documentary registration duties and naming lodging expressly11. Temporary closure is not only a regional tourism-law matter: the state guest-report regime reaches there too.
Liability falls directly on the obliged subject who committed the act (Article 8.4)10, so delegating the filing to an accountant or to software does not move it. The breakdown of degrees, limitation periods, who imposes the fine and the reduction for voluntary payment is in Penalties for non-compliance with RD 933/2021.
Catalonia and the Basque Country: the two regional registers
Most autonomous communities use the Ministry’s SES.HOSPEDAJES. There are two exceptions:
- Catalonia: reporting goes to the Mossos d’Esquadra through the Generalitat’s system.
- Basque Country: reporting goes to the Ertzaintza through the Basque Government’s system.
If your property is in either, the channel is the regional one and not SES.HOSPEDAJES. How each works is in Guest registration in Catalonia and the Basque Country.
FAQ
Since when is the SES.HOSPEDAJES guest report mandatory in Spain? The SES.HOSPEDAJES guest report has been mandatory in Spain since 2 December 2024, the date on which the Ministry of the Interior switched the register on after successive moratoriums. From then on, hotels, tourist apartments, rural houses, campgrounds, and vacation rentals listed on platforms like Airbnb or Booking must report each guest’s data electronically to the Spanish Ministry of the Interior. The old paper reports are no longer accepted.
How long do I have to submit a guest’s report? You have a maximum of 24 hours to submit a guest’s report. Article 6.3 counts that window from two moments: making the reservation or formalising the contract (or, where applicable, cancelling it), and the start of the contracted services. The communication must be made immediately within that window. Sending the report a week later is an untimely communication and therefore a minor infraction, fined €100 to €600.
Do I have to collect the guest’s card details? From the guest’s card you have to collect more than is usually assumed. For the lodging reservation, Annex I of RD 933/2021 includes the type of means (cash, card, payment platform, bank transfer), the holder and identification of the means: for a card, type and number; for a transfer, the IBAN. It adds the card’s expiry date and the date of payment. The CVV is not on the list and is never reported. The Annex asks for that block under both the professional and the non-professional regime, without conditioning it on the type of lodging or the length of the stay.
Does the guest have to be present for their data to be collected in Spain? The guest does not have to be present for their data to be collected. Spain’s Ministry of the Interior accepts any system that allows the accuracy of the data to be verified, even without physical presence, provided it is compatible with data protection rules, and it accepts devices that check identity remotely too. What does not change is who answers for that accuracy: Article 4.3 of RD 933/2021 still puts it on the establishment, so a remote check-in needs a verification mechanism, such as the traveller’s digital certificate, a check against the payment method details, or a code sent to their phone.
When must guest data be deleted? Guest data must be deleted after three years counted from the end of the contracted service: once that period passes it has to be erased or anonymised, because the retention period is fixed by the rule and keeping it longer without an additional legal basis would breach GDPR. The sensible approach is software that purges automatically rather than relying on manual deletion.
How RegistroViajero simplifies compliance
RegistroViajero automates the entire RD 933/2021 process:
- Digital check-in: each guest receives a unique link on their phone, fills in their details and signs an accuracy declaration, in 9 languages. No document photo to upload: the Annex I fields are typed in, by design.
- Automatic validation: the system checks that all mandatory fields are complete and valid before allowing submission.
- Direct submission to SES.HOSPEDAJES: generates and sends the reports to the Ministry with one click. No manual intervention.
- Status tracking: queries the result of each submission and notifies you of errors or rejections.
- Reservation import: syncs your reservations from Booking.com, Airbnb, VRBO, Expedia, Tripadvisor, and Google Calendar. Learn how to sync the portals via iCal.
The full end-to-end flow, from booking to Ministry submission and without setting up a tool yet, is in how to automate guest registration. If you’re choosing between tools, compare the options in the best guest registration apps for Spain. And the annual deposit under Order VAU/1560/2025 was filed against the NRUA, so the annulment of the registry left that report with no number to file against: what is left of that obligation.
This article is for informational purposes and does not replace professional legal advice.
Sources
-
Royal Decree 933/2021, of 26 October, on documentary registration and information duties for lodging and vehicle rental activities, consolidated text (BOE, in Spanish). ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Royal Decree 933/2021, third final provision, consolidated text (BOE, in Spanish). ↩
-
Interior activa el nuevo registro de hospedaje y alquiler de vehículos, press release of 2 December 2024 (Spanish Ministry of the Interior, La Moncloa). ↩ ↩2
-
Preguntas frecuentes de hospedajes y alquiler de vehículos, questions 6, 10, 12, 18, 19 and 22, version 09/04/2025 (Spanish Ministry of the Interior, PDF, in Spanish), accessed 8 September 2026. ↩ ↩2 ↩3 ↩4 ↩5 ↩6
-
Royal Decree 933/2021, Article 6, paragraphs 1 to 4 (BOE, in Spanish). ↩ ↩2 ↩3 ↩4 ↩5
-
Royal Decree 933/2021, Article 5, paragraphs 1, 3 and 4 (BOE, in Spanish). ↩ ↩2 ↩3
-
Royal Decree 933/2021, Annex I, sections A) and B), points 3 and 4 (BOE, in Spanish). ↩ ↩2 ↩3
-
AEPD note on copies of identity documents in lodgings, 17 June 2025, PDF (AEPD, in Spanish). ↩
-
Decreto 4/2026, de 2 de febrero, first amendment of Decreto 48/2016, article 13.2, BOPA no. 28 of 11 February 2026 (Principado de Asturias, PDF, in Spanish). ↩
-
Organic Law 4/2015, of 30 March, on the protection of public safety, Articles 25 and 39, consolidated text (BOE, in Spanish). ↩ ↩2



